VLANs, Trunk y Voice VLAN - Verificación
Cómo comprobar que las VLANs, los troncales y la VLAN de voz quedaron bien. La configuración está en VLANs, Trunk y Voice VLAN - Configuración y el diagnóstico en VLANs, Trunk y Voice VLAN - Troubleshooting.
| Quiero comprobar… | Comando |
|---|---|
| Qué VLANs existen y qué puertos de acceso tienen | show vlan brief |
| Modo, VLAN de acceso, VLAN de voz y nativa de un puerto | show interfaces <if> switchport |
| Qué troncales hay, su nativa y sus VLANs permitidas | show interfaces trunk |
| Qué negoció DTP en un puerto | show dtp interface <if> |
| Si un equipo se aprende en la VLAN correcta | show mac address-table vlan <n> |
| Si el teléfono IP está conectado | show cdp neighbors |
VLANs
Lista de VLANs y sus puertos
Switch# show vlan brief
Salida típica:
VLAN Name Status Ports
---- -------------------- --------- -------------------------------
1 default active Fa0/2, Fa0/3, Fa0/4, Fa0/5
Fa0/6, Fa0/7, Fa0/8, Fa0/9
... (resto de puertos no asignados)
Gi0/1, Gi0/2, Gi0/3, Gi0/4
10 VLAN_INGENIEROS active Fa0/1
20 VLAN0020 active
1002 fddi-default act/unsup
1003 token-ring-default act/unsup
1004 fddinet-default act/unsup
1005 trnet-default act/unsup
Cómo leerla:
- Cada VLAN aparece con su número, nombre y Status.
- Debajo de Ports se listan los puertos de acceso de esa VLAN. Los puertos no asignados siguen en la VLAN 1 (
default). - Los troncales no aparecen aquí, porque transportan varias VLANs. Para ellos se usa
show interfaces trunk. - Status:
active: VLAN operativa.act/unsup: activa pero no soportada; es lo normal en las reservadas 1002-1005 (Token Ring y FDDI).suspended: la VLAN está suspendida y no reenvía.
- Una VLAN creada sin nombre (por ejemplo la 20) aparece con el nombre por defecto
VLAN0020.
Para la tabla completa, con más detalle: Switch# show vlan
Puerto de acceso y su VLAN
Switch# show interfaces fastEthernet 0/1 switchport
Salida típica (recortada):
Name: Fa0/1
Switchport: Enabled
Administrative Mode: static access
Operational Mode: static access
Administrative Trunking Encapsulation: negotiate
Operational Trunking Encapsulation: native
Negotiation of Trunking: Off
Access Mode VLAN: 10 (VLAN_INGENIEROS)
Trunking Native Mode VLAN: 1 (default)
Voice VLAN: none
| Qué mirar | Valor esperado | Significado |
|---|---|---|
| Operational Mode | static access | El puerto funciona como de acceso |
| Access Mode VLAN | 10 (VLAN_INGENIEROS) | La VLAN de acceso y su nombre. Aquí se detecta un puerto en la VLAN equivocada |
| Negotiation of Trunking | Off | No intenta negociar troncal (correcto en un puerto de usuario) |
Configuración aplicada al puerto
Switch# show running-config interface fastEthernet 0/1
Debe mostrar switchport mode access y switchport access vlan 10.
MAC aprendidas por VLAN
Switch# show mac address-table vlan 10
Confirma que la MAC del equipo aparece en el puerto correcto y bajo la VLAN 10.
Trunk y DTP
Ver los enlaces troncales
Switch# show interfaces trunk
Salida típica:
Port Mode Encapsulation Status Native vlan
Fa0/10 on 802.1q trunking 99
Port Vlans allowed on trunk
Fa0/10 10,20,30,99
Port Vlans allowed and active in management domain
Fa0/10 10,20,30,99
Port Vlans in spanning tree forwarding state and not pruned
Fa0/10 10,20,30,99
Cómo leerla:
| Campo | Significado |
|---|---|
| Mode | on (troncal fijo), auto o desirable (negociación DTP) |
| Encapsulation | 802.1q (dot1q) |
| Status | trunking = troncal operativo. not-trunking = el enlace quedó de acceso |
| Native vlan | La VLAN nativa. Debe coincidir con el otro extremo |
| Vlans allowed on trunk | Lo que configuraste como permitido |
| Vlans allowed and active | De las permitidas, cuáles existen y están activas en este switch |
| Vlans in spanning tree forwarding | Cuáles están realmente reenviando (no bloqueadas por STP ni podadas) |
Si una VLAN está en “allowed” pero no en “allowed and active”, es que no existe en ese switch.
Detalle del puerto troncal
Switch# show interfaces fastEthernet 0/10 switchport
| Qué mirar | Significado |
|---|---|
| Administrative Mode | Lo que configuraste (trunk, dynamic auto, etc.) |
| Operational Mode | Cómo quedó realmente (trunk o static access) |
| Operational Trunking Encapsulation | dot1q |
| Negotiation of Trunking | Off si pusiste nonegotiate; On si DTP está activo |
| Trunking Native Mode VLAN | La VLAN nativa operativa |
| Trunking VLANs Enabled | Las VLANs permitidas en el troncal |
Aquí confirmas si el enlace realmente quedó troncal (
Operational Mode: trunk) o si por negociación terminó en acceso.
Estado de DTP en el puerto
Switch# show dtp interface fastEthernet 0/10
Salida típica:
DTP information for FastEthernet0/10:
TOS/TAS/TNS: ACCESS/AUTO/ACCESS
TOT/TAT/TNT: NATIVE/NEGOTIATE/NATIVE
Neighbor address 1: 3037A6797F0C
Neighbor address 2: 000000000000
Hello timer expiration (sec/state): 19/RUNNING
...
FSM state: S2:ACCESS
Enabled: yes
In STP: no
- TOS/TAS/TNS = Trunk Operational / Administrative / Negotiated Status. En el ejemplo,
ACCESS/AUTO/ACCESS: administrativamente está enauto, pero quedó enaccess(no formó troncal). - TOT/TAT/TNT = lo mismo para el tipo de encapsulación.
- Enabled: yes: DTP está activo en el puerto. Con
nonegotiatedeja de enviar tramas. - FSM state: estado final de la negociación (
ACCESSoTRUNK).
Voice VLAN
Detalle del puerto (datos + voz)
Switch# show interfaces fastethernet 0/10 switchport
| Qué mirar | Valor esperado | Significado |
|---|---|---|
| Operational Mode | static access | Sigue siendo un puerto de acceso, con la voz como VLAN auxiliar |
| Access Mode VLAN | 20 | La VLAN de datos (la PC) |
| Voice VLAN | 30 | La confirmación de que la voz quedó bien |
El puerto no aparece como troncal
Switch# show interfaces fastethernet 0/10 trunk
Un puerto de acceso con VLAN de voz normalmente no aparece como troncal en este comando, porque no es un trunk real. La confirmación definitiva es el campo
Voice VLANdeshow interfaces ... switchport.
VLANs de datos y voz
Switch# show vlan brief
Las dos VLANs (datos y voz) deben existir y estar active.
Teléfono y alimentación
! El teléfono IP debe verse como vecino CDP (capability Phone)
Switch# show cdp neighbors
! Si el teléfono se alimenta por PoE
Switch# show power inline
Switch# show power inline fastethernet 0/10
En show power inline el puerto debe estar entregando energía (on) con la potencia asignada. PoE se amplía en PoE - Verificación.
Confianza de QoS (si se configuró)
Switch# show mls qos interface fastethernet 0/10
Confirma que el puerto confía en el marcado del teléfono (trust). Ver QoS - Verificación.
Checklist de verificación
VLANs
-
show vlan brief: la VLAN existe, estáactivey con el nombre correcto. -
show vlan brief: el puerto aparece bajo la VLAN esperada (no bajo la 1). -
show interfaces <if> switchport:Operational Mode: static accessyAccess Mode VLANcorrecta. -
show mac address-table vlan <n>: la MAC del equipo se aprende en la VLAN correcta.
Trunk y DTP
-
show interfaces trunk: el puerto aparece comotrunking, con802.1qy la nativa correcta. - La nativa coincide en ambos extremos.
- Las VLANs permitidas son exactamente las que deben cruzar, y aparecen en “allowed and active”.
-
show interfaces <if> switchport:Operational Mode: trunkyNegotiation of Trunking: Offsi usaste nonegotiate. -
show dtp interface <if>: el estado negociado (TOS) es el que buscabas.
Voice VLAN
-
show interfaces <if> switchport:Access Mode VLAN(datos) yVoice VLAN(voz) correctas. -
show cdp neighbors: el teléfono aparece con capabilityPhone. - La VLAN de voz está permitida en los troncales hacia el servidor de telefonía.